T1087Tactic: DiscoveryOfficial MITRE ATT&CK Page

T1087: Account Discovery

Adversaries may attempt to get a listing of local system or domain accounts to orient themselves within an environment.

Total Capable Binaries: 1
Windows: 0
Linux: 0
macOS: 1

Living-off-the-Land Matrix for T1087

Across 1 verified binaries
macOS1 payloads

dscl

Directory Service command-line utility (dscl) allows reading and writing Directory Service databases. Attackers use dscl for local user discovery, creating hidden administrator accounts, or extracting password hashes.

Sample Attack Vector:
dscl . -create /Users/sysadmin UserShell /bin/zsh && dscl . -append /Groups/admin GroupMembership sysadmin
Sharon Ben Moshe
Curated & Verified by
Sharon Ben Moshe
Cybersecurity Researcher & Detection EngineerCheck Point